PT-2014-2032 · Yokogawa · Yokogawa Centum Cs 3000

Published

2014-03-14

·

Updated

2025-09-25

·

CVE-2014-0781

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Yokogawa CENTUM CS 3000 versions R3.09.50 and earlier
Description The issue is related to a heap-based buffer overflow in the BKCLogSvr.exe service, which can be exploited by sending crafted UDP packets. This allows remote attackers to execute arbitrary code and potentially elevate their privileges. The vulnerability can be triggered by sending a specially crafted packet to port 52302/UDP.
Recommendations For Yokogawa CENTUM CS 3000 versions R3.09.50 and earlier, consider restricting access to the BKCLogSvr.exe service and port 52302/UDP to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05458
CVE-2014-0781

Affected Products

Yokogawa Centum Cs 3000